class ApplicationController < ActionController::Base


  # Prevent CSRF attacks by raising an exception.
  # For APIs, you may want to use :null_session instead.
  protect_from_forgery with: :exception

  def after_sign_in_path_for(resource)
    request.env['omniauth.origin'] || stored_location_for(resource) || (current_user.role.in?(['manager', 'admin']) ? sales_url : root_url)
  end

  rescue_from CanCan::AccessDenied do |exception|
    # redirect_to main_app.root_url, :alert => exception.message
    # render 'shared/access_denied'
    redirect_to main_app.root_url, :alert => '访问被拒绝'
  end


  def user_for_paper_trail
    user_signed_in? ? current_user.id : 'Public user'
  end
end
